10 September 2026
8 min read
Registration in the National Cybersecurity System (KSC) register by 3 October 2026. Check whether your company may be subject to the new obligation.

Registration in the KSC (NIS2) register is due by 3 October 2026. Find out if your company is covered by this obligation and what penalties apply.
The amendment to the Act on the National Cybersecurity System, implementing the NIS2 Directive, entered into force on 3 April 2026 (Act of 23 January 2026, Journal of Laws item 252). Self-registration in the Register of Key Entities and Important Entities began on 7 May, and the deadline for submitting an application expires on 3 October 2026. It is estimated that the new provisions will cover approximately 38,000 entities, of which approximately 11,000 are non-public entities. According to information that has reached the public domain, in the first two months of the register's operation only around two hundred companies had registered.
Determining whether a given entity is subject to the obligation requires carrying out a two-stage test independently, and the result may surprise more than one company. Above all, it may concern firms from sectors which, until now, had nothing to do with regulatory cybersecurity.
Why won't anyone notify you about this?
The model adopted in the Act is based on self-identification. The Minister of Digital Affairs registers some entities ex officio, and these are primarily public entities, telecommunications operators, trust service providers and existing operators of key services. The rest — the vast majority of private companies — must assess their own situation independently and submit the appropriate application themselves.
The burden of correct qualification therefore rests on the entrepreneur. There is no point expecting to receive a summons or any other kind of letter informing you of the requirement to fulfil this obligation. Moreover, the absence of registration does not mean the company is not subject to the provisions. If it meets the statutory criteria, the obligations arise by operation of law, regardless of whether registration has actually taken place.
It is worth noting straight away that the registration application contains a declaration by the entity's manager made under threat of criminal liability for submitting a false declaration (Article 7c(5) of the KSC Act).
Step one: does your company operate in a sector covered by the Act?
The Act divides sectors into "key" (Annex 1 to the Act) and "important" (Annex 2 to the Act), and the entity's subsequent classification depends on this division.
Annex 1 covers sectors of high criticality: energy, transport, banking and financial market infrastructure, healthcare, drinking water supply and wastewater management, digital infrastructure, ICT service management, public administration and space.
Annex 2 covers important sectors, but of lower criticality: postal services, waste management, the production and distribution of chemicals, the production, processing and distribution of food, production in selected industries, digital service providers and research activity.
The description of sectors is often broader than the name alone suggests. Food is a good example: the annex covers food businesses engaged in wholesale distribution and industrial production and processing. An entity that does not carry out its own production may therefore also be covered.
When verifying the sector, what counts is the actual type of activity conducted, not merely the PKD code for the predominant activity disclosed in the register relevant for the entity. It is also worth remembering that an extensive list of codes is not a basis for exempting oneself from the obligations. The opposite may in fact be true: it may mean that the company operates in several covered sectors simultaneously.
Step two: do you exceed the size thresholds?
The size criterion is based on definitions from EU law, specifically Article 2(1) of Annex I to Commission Regulation (EU) No 651/2014. The simplified test is as follows: the obligation arises if the company employs at least 50 employees, or achieves an annual turnover exceeding EUR 10 million, or its total balance sheet exceeds EUR 10 million. Meeting just one of these conditions is enough.
The combination of sector and size determines the entity's status. A key entity is, as a rule, an entrepreneur from a sector covered by Annex 1 that exceeds the requirements set for a medium-sized enterprise. An important entity is an entrepreneur from a sector covered by Annex 1 that merely meets those requirements, as well as an entrepreneur from a sector covered by Annex 2 that meets or exceeds them. Belonging to a key sector therefore does not automatically determine key-entity status. The difference is not merely nominal: key entities are subject to preventive supervision and a cyclical audit obligation, and the penalty limits for them are higher.
The situation of related entities
This is an issue on which companies most often make a mistake, assuming that in their case the registration obligation has not arisen.
The size thresholds are assessed according to the rules known from the EU definition of small and medium-sized enterprises. These rules require taking into account not only the data of the entity itself, but also the data of partner and linked enterprises. In the case of a linked enterprise — one in which another entity holds a majority of the voting rights — the data of the controlling entity is added to the company's own data.
The consequence is far-reaching. A company with revenues in the range of a few million złoty, employing a dozen or so people, does not exceed any threshold when assessed in isolation. If, however, it forms part of a capital group and the controlling entity holds a majority stake in it, the thresholds may be exceeded with a large margin. This applies in particular to special-purpose vehicles or "joint ventures" set up by larger groups to handle a specific brand or business line.
The practical conclusion is that qualification should not be carried out solely on the basis of the company's own financial statements and an employment audit. The ownership structure must be established and the data of related entities obtained, above all at the ownership level.
When can the obligation arise despite the thresholds not being met?
Besides the test described above, the Act provides for a separate mechanism. Under Article 7l of the KSC Act, the authority responsible for cybersecurity matters may, by decision, recognise an entity as key or important despite the standard criteria not being met, if it carries out the activity specified in Annex 1 or 2 and meets at least one of the special conditions.
These include situations in which an entity is the sole provider of a service of key importance for critical social or economic activity, where a disruption to the service it provides would cause a serious threat to state security, public order, defence or public health, or a systemic risk of the cessation of service provision by other key or important entities, as well as situations in which the service provided is of significant importance at the regional or national level or is significant for two or more sectors.
This is therefore not an element of self-assessment but a competence of the authority. The decision is subject to immediate enforcement, and in it the authority calls on the entity to supplement the data in the register within 6 months, under threat of a financial penalty.
Verification of contracts and counterparties
Even a negative test result does not close the matter. Key and important entities have an obligation to manage supply chain security, which includes assessing suppliers and incorporating security requirements into the contracts they conclude.
As a result, the Act's requirements can, in a certain sense, affect companies formally not covered by the Act. If you are a supplier, subcontractor or service provider to an entity subject to the provisions, you may encounter attempts to, for example, renegotiate contracts, precisely in order to introduce solutions and requirements related to ensuring cybersecurity.
What penalties apply for failing to register?
Failure to submit a registration application is a breach of a statutory obligation. The Act explicitly lists it among the breaches for which a financial penalty may be imposed on the manager of a key or important entity (Article 73a(1)(1) in conjunction with Article 7c(1)). This penalty may be imposed in an amount not exceeding 300 percent of the remuneration of the penalised person, and in public entities up to 100 percent.
Penalties against the entities themselves vary according to status. For a key entity they may reach EUR 10 million or 2 percent of annual turnover, whichever is higher, with a minimum penalty of PLN 20,000. For an important entity, this is EUR 7 million or 1.4 percent of turnover respectively, with a minimum penalty of PLN 15,000. The Act also provides for a penalty of up to PLN 100 million where a breach causes a direct and serious cyber threat to defence, state security, public security and order, or human life and health, or a risk of causing serious property damage or serious disruption to the provision of services.
There is, however, a transitional proviso that is rarely discussed. Under Article 35 of the amendment, the financial penalties provided for in Article 73(1)–(4) and Articles 73a–73c may be imposed for the first time only after 2 years have elapsed from the date the Act entered into force, i.e. after 3 April 2028. This proviso does not, however, extend to the penalty of up to PLN 100 million provided for in Article 73(5). The transitional period does not mean a suspension of supervision, since inspections, requests and orders remain available immediately.
Management liability has been regulated separately. The Act introduces personal liability for the manager of a key or important entity for performing cybersecurity obligations, including submitting the registration application. Two solutions deserve particular attention here. First, if the manager is a multi-person body and no responsible person has been designated, all members of that body bear liability. Second, the manager also bears liability where the duties have been entrusted to another person with that person's consent. Entrusting tasks to the company's own IT department or an external supplier therefore does not release the manager from liability.
Where to start?
Start by comparing your company's actual activity profile with Annexes 1 and 2 to the Act, taking into account all types of activity conducted, not only the predominant one. Then establish the size of the enterprise, necessarily taking into account the ownership structure and the data of related entities. If you operate in a sector covered by the annexes but do not exceed the thresholds, bear in mind the possibility of being made subject to the obligation by a decision of the authority under Article 7l of the Act.
If the result is positive, the application is submitted electronically through the KSC Register application, which forms part of the S46 system. Registration is free of charge and formal in nature. Also remember the obligation to report changes to the data disclosed in the register, for which the Act provides a 14-day deadline.
The 3 October deadline concerns the simplest task in the entire package of obligations, and yet it remains unfulfilled by the vast majority of those obliged. It is worth treating it not merely as a box to be "ticked off" — especially since, in the event of a dispute over qualification, an entity that has registered is in a better position than one that has to explain why it considered the provisions did not apply to it, thereby exposing itself, together with the persons responsible for reporting, to certain consequences.
Questions? Feel free to get in touch.

Jan Matusiak
Attorney at Law
Author
Jan Matusiak
Attorney at Law
Attorney at law in Kraków, member of the Regional Bar Association (OIRP).